<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Mahesh, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cannot-ping-server-from-firewall/m-p/2918606#M157012</link>
    <description>&lt;P&gt;Hi Mahesh,&lt;/P&gt;
&lt;P&gt;I believe your ping is reaching the firewall, because your log shows it is getting denied. That is a good sign that the ping is getting there.&lt;/P&gt;
&lt;P&gt;Do you have an access-list built allowing the two networks to talk to each other?&lt;/P&gt;
&lt;P&gt;"access-list MY-INSIDE-ACL extended permit ip object 10.68.49.x object 10.68.55.105"&lt;/P&gt;
&lt;P&gt;and&lt;/P&gt;
&lt;P&gt;Have you applied the access-list to your inside interface?&lt;/P&gt;
&lt;P&gt;"access-group MY-INSIDE-ACL in interface inside"&lt;/P&gt;
&lt;P&gt;Also, does your switch have IP Routing enabled? If the ping is getting to the firewall and you have a good access-list (running packet tracer can confirm this, as m.kafka suggests), perhaps the switch is not allowing the ping to return from the firewall?&lt;/P&gt;</description>
    <pubDate>Tue, 12 Jul 2016 20:48:08 GMT</pubDate>
    <dc:creator>John Forester</dc:creator>
    <dc:date>2016-07-12T20:48:08Z</dc:date>
    <item>
      <title>Cannot ping server from firewall</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ping-server-from-firewall/m-p/2918603#M157009</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Here is setup&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;ASA---inside interface-10.68.49.x-----------------------------------Switch--------------------------------server&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;ASA inside interface has default route which points to switch.&lt;/P&gt;
&lt;P&gt;From switch I can ping the server address 10.68.55.105&lt;/P&gt;
&lt;P&gt;I can ping the ASA inside interface IP from switch.&lt;/P&gt;
&lt;P&gt;But from ASA I can not ping it.&lt;/P&gt;
&lt;P&gt;when from server we try ping it does notwork&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;ASA-3-313001: Denied ICMP type=8, code=0 from 10.68.55.105 on interface inside&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;MAhesh&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:00:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ping-server-from-firewall/m-p/2918603#M157009</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2019-03-12T08:00:46Z</dc:date>
    </item>
    <item>
      <title>You are probably missing a</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ping-server-from-firewall/m-p/2918604#M157010</link>
      <description>&lt;P&gt;You are probably missing a route to 10.68.55.x network on your ASA! To tell more, please post your sh run int and sh run route&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2016 02:17:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ping-server-from-firewall/m-p/2918604#M157010</guid>
      <dc:creator>Pavel Trinos</dc:creator>
      <dc:date>2016-07-12T02:17:57Z</dc:date>
    </item>
    <item>
      <title>Mahesh,</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ping-server-from-firewall/m-p/2918605#M157011</link>
      <description>&lt;P&gt;Mahesh,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;can you give a bit more details? Your setup looks unusual to me or I made wrong assumptions:&lt;/P&gt;
&lt;P&gt;What's the subnet mask and IP addresses for all devices? (I assume /24 should be on all interfaces).&lt;/P&gt;
&lt;P&gt;What's the output from packet tracer?&lt;/P&gt;
&lt;P&gt;313001 is explained here &lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa80/system/message/logmsgs.html#wp4771105" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/system/message/logmsgs.html#wp4771105&lt;/A&gt; :&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;&lt;SPAN class="pEM_ErrMsg"&gt;&lt;SPAN class="cBoldNormal"&gt;Error Message&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt; %PIX|ASA-3-313001: Denied ICMP type=&lt;EM class="cCi_CmdItalic"&gt;number&lt;/EM&gt;, code=&lt;EM class="cCi_CmdItalic"&gt;code&lt;/EM&gt; from &lt;EM class="cCi_CmdItalic"&gt;IP_address&lt;/EM&gt; 
on interface &lt;EM class="cCi_CmdItalic"&gt;interface_name
&lt;/EM&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN class="content"&gt;&lt;A name="wp4771108"&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="pEE_ErrExp"&gt;&lt;SPAN class="cBoldNormal"&gt;Explanation&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt; When using the &lt;SPAN style="color: black; font-style: normal; font-weight: bold;"&gt;icmp&lt;/SPAN&gt; command with an access list, if the first matched entry is a permit entry, the ICMP packet continues processing. If the first matched entry is a deny entry or an entry is not matched, the security appliance discards the ICMP packet and generates this syslog message. The &lt;B class="cBold"&gt;icmp&lt;/B&gt; command enables or disables pinging to an interface. With pinging disabled, the security appliance cannot be detected on the network. This feature is also referred to as configurable proxy pinging.&lt;/P&gt;
&lt;P class="pEE_ErrExp"&gt;Maybe give us a running config with all sensitive information removed (like public IPs, usernames, passwords, even encrypted etc.)&lt;/P&gt;
&lt;P class="pEE_ErrExp"&gt;&lt;/P&gt;
&lt;P class="pEE_ErrExp"&gt;Rgds, MiKa&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="content"&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2016 20:14:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ping-server-from-firewall/m-p/2918605#M157011</guid>
      <dc:creator>m.kafka</dc:creator>
      <dc:date>2016-07-12T20:14:40Z</dc:date>
    </item>
    <item>
      <title>Hi Mahesh,</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ping-server-from-firewall/m-p/2918606#M157012</link>
      <description>&lt;P&gt;Hi Mahesh,&lt;/P&gt;
&lt;P&gt;I believe your ping is reaching the firewall, because your log shows it is getting denied. That is a good sign that the ping is getting there.&lt;/P&gt;
&lt;P&gt;Do you have an access-list built allowing the two networks to talk to each other?&lt;/P&gt;
&lt;P&gt;"access-list MY-INSIDE-ACL extended permit ip object 10.68.49.x object 10.68.55.105"&lt;/P&gt;
&lt;P&gt;and&lt;/P&gt;
&lt;P&gt;Have you applied the access-list to your inside interface?&lt;/P&gt;
&lt;P&gt;"access-group MY-INSIDE-ACL in interface inside"&lt;/P&gt;
&lt;P&gt;Also, does your switch have IP Routing enabled? If the ping is getting to the firewall and you have a good access-list (running packet tracer can confirm this, as m.kafka suggests), perhaps the switch is not allowing the ping to return from the firewall?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2016 20:48:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ping-server-from-firewall/m-p/2918606#M157012</guid>
      <dc:creator>John Forester</dc:creator>
      <dc:date>2016-07-12T20:48:08Z</dc:date>
    </item>
    <item>
      <title>there was an access list on</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ping-server-from-firewall/m-p/2918607#M157013</link>
      <description>&lt;P&gt;there was an access list on inside interface for ping traffic &amp;nbsp;and when I added server subnet to it&amp;nbsp; worked fine.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2016 21:24:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ping-server-from-firewall/m-p/2918607#M157013</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2016-07-12T21:24:45Z</dc:date>
    </item>
  </channel>
</rss>

